By Jackson Godwin | Cybersecurity Analyst & Penetration Tester
For decades, modern cybersecurity has relied on encryption to protect sensitive information. From online banking and cloud computing to email and healthcare systems, encryption is the foundation of digital trust.
However, a new technological shift is approaching that could fundamentally change cybersecurity: quantum computing.
While large-scale quantum computers capable of breaking today’s encryption are not yet widely available, organizations, including banks, telecom operators, and public sector agencies across Nigeria, are already preparing for what is known as post-quantum risk.
In this guide, you’ll learn what post-quantum risk is, why it matters, which industries are most affected, and the practical steps businesses can take today, including considerations relevant to organizations operating under Nigerian and regional regulatory frameworks.
What Is Post-Quantum Risk?
Post-quantum risk refers to the cybersecurity risks that arise when powerful quantum computers become capable of breaking many of the cryptographic algorithms currently used to protect digital systems.
Most modern encryption depends on mathematical problems that are extremely difficult for today’s classical computers to solve.
Quantum computers could solve some of these problems much more efficiently, making certain widely used encryption methods vulnerable.
Why Is Quantum Computing a Cybersecurity Concern?
Today’s encryption protects:
- Online banking
- Cloud services
- Government communications
- Medical records
- Corporate data
- Cryptocurrency systems
- VPN connections
- Digital signatures
Many of these systems rely on public-key cryptography, which is especially vulnerable to future quantum attacks.
If these algorithms become breakable, attackers could potentially:
- Read encrypted communications
- Forge digital signatures
- Impersonate trusted systems
- Steal confidential information
- Undermine software integrity
Which Encryption Algorithms Are Most at Risk?
The following public-key algorithms are expected to be vulnerable to sufficiently capable quantum computers:
- RSA
- Elliptic Curve Cryptography (ECC)
- Diffie-Hellman
- Elliptic Curve Diffie-Hellman (ECDH)
These algorithms are widely used for:
- HTTPS websites
- VPN authentication
- Email encryption
- Digital certificates
- Secure software updates
Symmetric encryption algorithms such as AES are generally considered more resistant to quantum attacks, although larger key sizes are expected to provide stronger long-term protection.
Understanding the “Harvest Now, Decrypt Later” Threat
One of the biggest concerns is known as Harvest Now, Decrypt Later.
In this scenario:
- An attacker intercepts encrypted communications today.
- The attacker stores the encrypted data.
- Once practical quantum computers become available, the attacker attempts to decrypt the stored information.
This means sensitive information with a long confidentiality lifespan, such as government records, intellectual property, or medical data, could remain at risk even if it is encrypted today. For Nigerian organizations, this is particularly relevant to data held under NDPA 2023 obligations, where personal data may need to remain confidential for many years.
Industries Most at Risk
Organizations handling highly sensitive information should pay particular attention to post-quantum planning. Examples include:
- Financial institutions
- Healthcare providers
- Government agencies
- Defense organizations
- Telecommunications companies
- Cloud service providers
- Critical infrastructure operators
- Technology companies
Any business with data that must remain confidential for many years should assess its exposure. In Nigeria, this is especially relevant for CBN-regulated financial institutions, NCC-licensed telecom operators, and oil and gas companies operating under NUPRC oversight, given the long confidentiality lifespan of financial, subscriber, and operational data.
What Is Post-Quantum Cryptography (PQC)?
Post-Quantum Cryptography (PQC) refers to cryptographic algorithms designed to remain secure against attacks from both classical and quantum computers.
Unlike quantum cryptography, PQC can generally be implemented on existing computer systems through software and hardware updates.
Researchers and standards organizations, including the U.S. National Institute of Standards and Technology (NIST), have been working to identify and standardize algorithms suitable for long-term use.
Why Businesses Should Prepare Now
Although large-scale quantum attacks are not an immediate reality, preparing early can reduce future disruption.
Reasons to begin planning include:
- Long system replacement cycles
- Long-lived encrypted data
- Regulatory expectations
- Customer trust
- Supply chain requirements
Organizations that understand where cryptography is used in their environment will be better positioned to transition when necessary.
How to Assess Post-Quantum Risk
A structured assessment may include:
1. Inventory Cryptographic Assets
Identify where cryptography is used, including:
- Web applications
- VPNs
- Databases
- Email systems
- APIs
- Certificates
- Cloud platforms
2. Classify Sensitive Data
Determine which information requires long-term confidentiality. Examples include:
- Customer records
- Intellectual property
- Trade secrets
- Government information
- Financial transactions
3. Identify Vulnerable Algorithms
Document systems relying on:
- RSA
- ECC
- Diffie-Hellman
Understanding where these algorithms are deployed helps prioritize future upgrades.
4. Engage Technology Vendors
Ask suppliers about their plans for supporting post-quantum cryptography. Questions may include:
- Do your products have a roadmap for PQC?
- How will cryptographic updates be delivered?
- What migration support will be available?
5. Develop a Migration Strategy
Organizations should plan for future cryptographic updates without assuming an immediate need to replace all systems. A phased approach can reduce operational risk.
Best Practices for Reducing Post-Quantum Risk
- Maintaining an inventory of cryptographic assets
- Monitoring developments in post-quantum cryptography
- Designing systems with cryptographic agility (the ability to replace algorithms more easily)
- Updating legacy systems where practical
- Including quantum readiness in long-term security planning
- Working closely with vendors and technology partners
Common Challenges
Preparing for post-quantum security may involve challenges such as:
- Legacy applications
- Complex supply chains
- Limited cryptographic visibility
- Vendor dependencies
- Budget constraints
- Skills shortages
Addressing these issues early can simplify future transitions.
Post-Quantum Risk and Compliance
Many cybersecurity frameworks encourage organizations to monitor emerging risks and maintain effective cryptographic controls. Examples include:
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- PCI DSS
- SOC 2
While these frameworks may not currently require post-quantum cryptography, they support risk-based planning and continual improvement. In Nigeria, this same risk-based approach aligns with NDPA 2023 accountability principles and NITDA guidance, encouraging organizations to keep pace with emerging technology risks, including quantum computing.
Future Trends
Key developments expected over the coming years include:
- Wider adoption of standardized post-quantum cryptographic algorithms
- Hybrid cryptographic deployments combining traditional and post-quantum methods
- Vendor support for quantum-resistant technologies
- Increased regulatory guidance
- Greater focus on cryptographic asset management
Organizations that begin planning now are likely to adapt more smoothly as the technology evolves.
Benefits of Early Preparation
Preparing for post-quantum risks can help organizations:
- Protect long-term confidential information
- Reduce future migration challenges
- Improve cybersecurity resilience
- Strengthen customer confidence
- Support long-term compliance planning
- Stay ahead of emerging threats
Final Thoughts
Quantum computing has the potential to transform many industries, including cybersecurity. While practical quantum attacks against today’s encryption are not yet commonplace, organizations should not wait until the technology matures before planning.
By understanding where cryptography is used, assessing long-term data risks, engaging vendors, and preparing for future cryptographic transitions, businesses, including those operating under Nigerian regulatory frameworks, can position themselves to respond effectively as post-quantum technologies evolve.
Post-quantum risk management is not about replacing every encryption system today; it is about building a roadmap that supports security, resilience, and trust in the years ahead.
Frequently Asked Questions (FAQ)
What is post-quantum risk?
Post-quantum risk refers to the possibility that future quantum computers could break some of the cryptographic algorithms widely used today, exposing sensitive information.
Is current encryption already broken by quantum computers?
No. Current large-scale quantum computers are not generally capable of breaking widely deployed public-key encryption in real-world operational environments today. However, organizations are preparing for future developments because some data must remain confidential for many years.
What is post-quantum cryptography?
Post-quantum cryptography consists of cryptographic algorithms designed to resist attacks from both classical and future quantum computers.
Which industries should prepare first?
Organizations that handle highly sensitive or long-lived information, such as financial institutions, healthcare providers, government agencies, cloud service providers, and critical infrastructure operators, should consider assessing their post-quantum readiness as part of their broader cybersecurity strategy.
ABOUT THE AUTHOR
Jackson Godwin is a Cybersecurity Analyst and Penetration Tester at Jackson Technology, a cybersecurity and data protection consulting firm based in Abuja, Nigeria, serving enterprise clients across banking, fintech, oil and gas, and the public sector. His expertise spans vulnerability assessment and penetration testing (VAPT), cloud security, and compliance advisory covering ISO 27001, the NDPA 2023, and GDPR. He is also affiliated with TechTrain Academy, where he supports cybersecurity education for African professionals.
info@jacksontechnology.com.ng | jacksontechnology.com.ng






